Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 10 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elated Themes
Elated Themes elated Membership Wordpress Wordpress wordpress |
|
| Vendors & Products |
Elated Themes
Elated Themes elated Membership Wordpress Wordpress wordpress |
Wed, 10 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.2. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'eltdf_membership_check_facebook_user' and the 'eltdf_membership_login_user_from_social_network' function. This makes it possible for unauthenticated attackers to log in as administrative users, as long as they have an existing account on the site which can easily be created by default through the temp user functionality, and access to the administrative user's email. | |
| Title | Elated Membership <= 1.2 - Authentication Bypass via Social Login | |
| Weaknesses | CWE-289 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-12-10T15:25:25.533Z
Reserved: 2025-11-24T17:18:21.090Z
Link: CVE-2025-13613
Updated: 2025-12-10T15:24:55.129Z
Status : Awaiting Analysis
Published: 2025-12-10T03:15:46.250
Modified: 2025-12-12T15:18:42.140
Link: CVE-2025-13613
No data.
OpenCVE Enrichment
Updated: 2025-12-10T17:48:50Z